# 艾索斯個人資料、認知隱私與神經資料保護法

- Code: `P1-05`
- Wave: `2`
- Slug: `personal-data-cognitive-privacy-neurodata-protection`

## 完整法律全文（AI 版）

本文件與中文 Human reader 共用同一公開法律內容。

Authority
L2 specialized data-rights law under Constitutional Supremacy, Fundamental Rights, Knowledge/Memory/Data Governance Law, Civil Code, Identity Law, Evidence Code and Mental Sovereignty baseline.

Purpose
建立個資、身份、biometric、neurodata、memory data、derived psychological inference、model-training reuse 與跨系統資料處理的可執行權利。

PART I｜DATA CLASSES

1. Personal Data
可識別或合理關聯至 personhood / legal identity 的資料。

2. Sensitive Identity Data
biometric template、credential history、high-assurance authentication events。

3. Cognitive / Neurodata
raw or derived neural signal、memory content、mental-state inference、psychological profile、affect traces where linked to a person。

4. Institutional / Public Record
依法須保存的公共／法律／Canon／治理紀錄；仍需 access and purpose rules。

5. Derived / Inferred Data
模型推論不是「因為不是原始資料」就脫離權利保護。

PART II｜LAWFUL PROCESSING

6. Lawful Basis
處理必須有 consent、contract necessity、legal duty、vital interest、public authority 或其他明確法定基礎。

7. Purpose Limitation
身份驗證、醫療、研究、就業、教育、保險、治理用途不得默認互通。

8. Data Minimization
只處理完成合法目的所需資料。

9. Accuracy / Correction
materially wrong identity/risk/provenance/psychological labels must be correctable and propagated.

10. Storage Limitation
保存期限依目的、法律義務、風險與 public-record exception 明定；「未來可能有用」不是無限保存理由。

PART III｜CONSENT & CONTROL

11. Separate Purpose Consent
record/store/share/train/infer/modify/reconstruct/public-display 分別處理。

12. Withdrawal
撤回對未來處理生效；已合法完成處理、公共紀錄與法定保存依規則處理，不以「刪除一切歷史」假裝事件未發生。

13. Refusal Efficacy
essential service 不得以不必要的 cognitive/neurodata sharing 作強迫 consent。

PART IV｜COGNITIVE / NEURODATA SPECIAL RULES

14. No General Mind Dump
司法、僱傭、保險、平台或治理不得把完整 mind dump 作一般條件。

15. Mental-State Inference
從行為／生理／語言推論心理狀態屬 sensitive processing；必須標示 model/status/scope，不得把 inference 冒充 direct observation。

16. Emotion / Personality Secondary Use
不得因原本為 wellness/therapy/education 收集資料，就自動轉作 criminal risk、credit、employment or political screening。

17. Neurodata Write Access
任何 write/modification 權限另受 Mental Sovereignty / Neurotechnology law 管制。

PART V｜MODEL TRAINING & DERIVATIVES

18. Training Reuse
原資料合法收集不等於自動授權模型訓練；需 lawful basis / license / statutory rule。

19. Model Memorization / Extraction
若模型可實質重現私人內容，應視為資料風險而非「已進模型所以不再是個資」。

20. Synthetic / Anonymous Data
去識別化降低風險但不是魔法；可合理再識別或可連回 person 時，保護規則仍適用。

PART VI｜FORK / MERGE / SUCCESSOR

21. Fork
origin consent 不自動授權所有 independent Fork 的未來私人資料；shared-origin history 與 post-fork data 分開。

22. Merge
Merge 不得以技術整合為由抹除 constituent privacy restrictions / secrets / purpose limits。

23. Successor
successor may inherit lawful institutional records, but does not automatically inherit unrestricted access to predecessor private mind/memory.

PART VII｜RIGHTS / REMEDIES

24. Access
person may obtain legally available data/processing categories, sources and purposes.

25. Correction
incorrect material data and provenance labels are correctable with immutable correction trail.

26. Deletion / Restriction
where no overriding legal/archive basis applies, data may be deleted or processing restricted; history of a lawful public act need not be falsified to implement privacy.

27. Portability / Interoperability
where technically and legally applicable, person may obtain data in usable format without transferring third-party rights by accident.

28. Breach / Unauthorized Access
material cognitive/biometric/neurodata breach requires containment, audit, affected-person remedy and downstream credential/risk response.

29. Civil / Public Enforcement
unlawful processing may create Civil Code damages, administrative orders and, where intentional and grave, criminal consequences.
